Merge pull request #20857 from github/post-release-prep/codeql-cli-2.23.6

Post-release preparation for codeql-cli-2.23.6
This commit is contained in:
Paolo Tranquilli
2025-11-18 15:14:39 +01:00
committed by GitHub
174 changed files with 471 additions and 165 deletions

View File

@@ -1,3 +1,7 @@
## 0.4.21
No user-facing changes.
## 0.4.20 ## 0.4.20
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.4.21
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 0.4.20 lastReleaseVersion: 0.4.21

View File

@@ -1,5 +1,5 @@
name: codeql/actions-all name: codeql/actions-all
version: 0.4.21-dev version: 0.4.22-dev
library: true library: true
warnOnImplicitThis: true warnOnImplicitThis: true
dependencies: dependencies:

View File

@@ -1,3 +1,7 @@
## 0.6.13
No user-facing changes.
## 0.6.12 ## 0.6.12
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.6.13
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 0.6.12 lastReleaseVersion: 0.6.13

View File

@@ -1,5 +1,5 @@
name: codeql/actions-queries name: codeql/actions-queries
version: 0.6.13-dev version: 0.6.14-dev
library: false library: false
warnOnImplicitThis: true warnOnImplicitThis: true
groups: [actions, queries] groups: [actions, queries]

View File

@@ -1,3 +1,13 @@
## 6.1.0
### New Features
* New predicates `getAnExpandedArgument` and `getExpandedArgument` were added to the `Compilation` class, yielding compilation arguments after expansion of response files.
### Bug Fixes
* Improve performance of the range analysis in cases where it would otherwise take an exorbitant amount of time.
## 6.0.1 ## 6.0.1
No user-facing changes. No user-facing changes.

View File

@@ -1,4 +0,0 @@
---
category: fix
---
* Improve performance of the range analysis in cases where it would otherwise take an exorbitant amount of time.

View File

@@ -1,4 +1,9 @@
--- ## 6.1.0
category: feature
--- ### New Features
* New predicates `getAnExpandedArgument` and `getExpandedArgument` were added to the `Compilation` class, yielding compilation arguments after expansion of response files. * New predicates `getAnExpandedArgument` and `getExpandedArgument` were added to the `Compilation` class, yielding compilation arguments after expansion of response files.
### Bug Fixes
* Improve performance of the range analysis in cases where it would otherwise take an exorbitant amount of time.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 6.0.1 lastReleaseVersion: 6.1.0

View File

@@ -1,5 +1,5 @@
name: codeql/cpp-all name: codeql/cpp-all
version: 6.0.2-dev version: 6.1.1-dev
groups: cpp groups: cpp
dbscheme: semmlecode.cpp.dbscheme dbscheme: semmlecode.cpp.dbscheme
extractor: cpp extractor: cpp

View File

@@ -1,3 +1,7 @@
## 1.5.4
No user-facing changes.
## 1.5.3 ## 1.5.3
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.5.4
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.5.3 lastReleaseVersion: 1.5.4

View File

@@ -1,5 +1,5 @@
name: codeql/cpp-queries name: codeql/cpp-queries
version: 1.5.4-dev version: 1.5.5-dev
groups: groups:
- cpp - cpp
- queries - queries

View File

@@ -1,3 +1,7 @@
## 1.7.52
No user-facing changes.
## 1.7.51 ## 1.7.51
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.52
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.7.51 lastReleaseVersion: 1.7.52

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-solorigate-all name: codeql/csharp-solorigate-all
version: 1.7.52-dev version: 1.7.53-dev
groups: groups:
- csharp - csharp
- solorigate - solorigate

View File

@@ -1,3 +1,7 @@
## 1.7.52
No user-facing changes.
## 1.7.51 ## 1.7.51
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.52
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.7.51 lastReleaseVersion: 1.7.52

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-solorigate-queries name: codeql/csharp-solorigate-queries
version: 1.7.52-dev version: 1.7.53-dev
groups: groups:
- csharp - csharp
- solorigate - solorigate

View File

@@ -1,3 +1,17 @@
## 5.4.0
### Deprecated APIs
* `ControlFlowElement.controlsBlock` has been deprecated in favor of the Guards library.
### New Features
* Initial support for incremental C# databases via `codeql database create --overlay-base`/`--overlay-changes`.
### Minor Analysis Improvements
* Updated *roslyn* and *binlog* dependencies in the extractor, which may improve database and analysis quality.
## 5.3.0 ## 5.3.0
### Deprecated APIs ### Deprecated APIs

View File

@@ -1,4 +0,0 @@
---
category: deprecated
---
* `ControlFlowElement.controlsBlock` has been deprecated in favor of the Guards library.

View File

@@ -1,5 +0,0 @@
---
category: feature
---
* Initial support for incremental C# databases via `codeql database create --overlay-base`/`--overlay-changes`.

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* Updated *roslyn* and *binlog* dependencies in the extractor, which may improve database and analysis quality.

View File

@@ -6,7 +6,7 @@
### Major Analysis Improvements ### Major Analysis Improvements
* The representation of the C# control-flow graph has been significantly changed. This has minor effects on a wide range of queries including both minor improvements and minor regressions, for example, improved precision has been observed for `cs/inefficient-containskey` and `cs/stringbuilder-creation-in-loop`. Two queries stand out as being significantly affected with great improvements: `cs/dereferenced-value-may-be-null` has been completely rewritten which removes a very significant number of false positives. Furthermore, `cs/constant-condition` has been updated to report many new results - these new results are primarily expected to be true positives, but a few new false positives are expected as well. As part of these changes, `cs/dereferenced-value-may-be-null` has been changed from a `path-problem` query to a `problem` query, so paths are no longer reported for this query. * The representation of the C# control-flow graph has been significantly changed. This has minor effects on a wide range of queries including both minor improvements and minor regressions. For example, improved precision has been observed for `cs/inefficient-containskey` and `cs/stringbuilder-creation-in-loop`. Two queries stand out as being significantly affected with great improvements: `cs/dereferenced-value-may-be-null` has been completely rewritten which removes a very significant number of false positives. Furthermore, `cs/constant-condition` has been updated to report many new results - these new results are primarily expected to be true positives, but a few new false positives are expected as well. As part of these changes, `cs/dereferenced-value-may-be-null` has been changed from a `path-problem` query to a `problem` query, so paths are no longer reported for this query.
### Minor Analysis Improvements ### Minor Analysis Improvements

View File

@@ -0,0 +1,13 @@
## 5.4.0
### Deprecated APIs
* `ControlFlowElement.controlsBlock` has been deprecated in favor of the Guards library.
### New Features
* Initial support for incremental C# databases via `codeql database create --overlay-base`/`--overlay-changes`.
### Minor Analysis Improvements
* Updated *roslyn* and *binlog* dependencies in the extractor, which may improve database and analysis quality.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 5.3.0 lastReleaseVersion: 5.4.0

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-all name: codeql/csharp-all
version: 5.3.1-dev version: 5.4.1-dev
groups: csharp groups: csharp
dbscheme: semmlecode.csharp.dbscheme dbscheme: semmlecode.csharp.dbscheme
extractor: csharp extractor: csharp

View File

@@ -1,3 +1,13 @@
## 1.5.0
### New Queries
* The `cs/web/cookie-secure-not-set` and `cs/web/cookie-httponly-not-set` queries have been promoted from experimental to the main query pack.
### Minor Analysis Improvements
* An improvement to the Guards library for recognizing disjunctions means improved precision for `cs/constant-condition`, `cs/inefficient-containskey`, and `cs/dereferenced-value-may-be-null`. The two former can have additional findings, and the latter will have fewer false positives.
## 1.4.3 ## 1.4.3
### Minor Analysis Improvements ### Minor Analysis Improvements

View File

@@ -1,4 +0,0 @@
---
category: newQuery
---
* The `cs/web/cookie-secure-not-set` and `cs/web/cookie-httponly-not-set` queries have been promoted from experimental to the main query pack.

View File

@@ -2,4 +2,4 @@
### Minor Analysis Improvements ### Minor Analysis Improvements
* the `cs/web/missing-x-frame-options` query now correctly handles configuration nested in root `<location>` elements. * The `cs/web/missing-x-frame-options` query now correctly handles configuration nested in root `<location>` elements.

View File

@@ -1,4 +1,9 @@
--- ## 1.5.0
category: minorAnalysis
--- ### New Queries
* The `cs/web/cookie-secure-not-set` and `cs/web/cookie-httponly-not-set` queries have been promoted from experimental to the main query pack.
### Minor Analysis Improvements
* An improvement to the Guards library for recognizing disjunctions means improved precision for `cs/constant-condition`, `cs/inefficient-containskey`, and `cs/dereferenced-value-may-be-null`. The two former can have additional findings, and the latter will have fewer false positives. * An improvement to the Guards library for recognizing disjunctions means improved precision for `cs/constant-condition`, `cs/inefficient-containskey`, and `cs/dereferenced-value-may-be-null`. The two former can have additional findings, and the latter will have fewer false positives.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.4.3 lastReleaseVersion: 1.5.0

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-queries name: codeql/csharp-queries
version: 1.4.4-dev version: 1.5.1-dev
groups: groups:
- csharp - csharp
- queries - queries

View File

@@ -1,3 +1,7 @@
## 1.0.35
No user-facing changes.
## 1.0.34 ## 1.0.34
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.0.35
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.0.34 lastReleaseVersion: 1.0.35

View File

@@ -1,5 +1,5 @@
name: codeql-go-consistency-queries name: codeql-go-consistency-queries
version: 1.0.35-dev version: 1.0.36-dev
groups: groups:
- go - go
- queries - queries

View File

@@ -1,3 +1,12 @@
## 5.0.2
### Bug Fixes
* Some fixes relating to use of path transformers when extracting a database:
* Fixed a problem where the path transformer would be ignored when extracting older codebases that predate the use of Go modules.
* The environment variable `CODEQL_PATH_TRANSFORMER` is now recognized, in addition to `SEMMLE_PATH_TRANSFORMER`.
* Fixed some cases where the extractor emitted paths without applying the path transformer.
## 5.0.1 ## 5.0.1
No user-facing changes. No user-facing changes.

View File

@@ -1,6 +1,7 @@
--- ## 5.0.2
category: fix
--- ### Bug Fixes
* Some fixes relating to use of path transformers when extracting a database: * Some fixes relating to use of path transformers when extracting a database:
* Fixed a problem where the path transformer would be ignored when extracting older codebases that predate the use of Go modules. * Fixed a problem where the path transformer would be ignored when extracting older codebases that predate the use of Go modules.
* The environment variable `CODEQL_PATH_TRANSFORMER` is now recognized, in addition to `SEMMLE_PATH_TRANSFORMER`. * The environment variable `CODEQL_PATH_TRANSFORMER` is now recognized, in addition to `SEMMLE_PATH_TRANSFORMER`.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 5.0.1 lastReleaseVersion: 5.0.2

View File

@@ -1,5 +1,5 @@
name: codeql/go-all name: codeql/go-all
version: 5.0.2-dev version: 5.0.3-dev
groups: go groups: go
dbscheme: go.dbscheme dbscheme: go.dbscheme
extractor: go extractor: go

View File

@@ -1,3 +1,7 @@
## 1.4.9
No user-facing changes.
## 1.4.8 ## 1.4.8
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.4.9
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.4.8 lastReleaseVersion: 1.4.9

View File

@@ -1,5 +1,5 @@
name: codeql/go-queries name: codeql/go-queries
version: 1.4.9-dev version: 1.4.10-dev
groups: groups:
- go - go
- queries - queries

View File

@@ -1,3 +1,7 @@
## 7.7.4
No user-facing changes.
## 7.7.3 ## 7.7.3
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 7.7.4
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 7.7.3 lastReleaseVersion: 7.7.4

View File

@@ -1,5 +1,5 @@
name: codeql/java-all name: codeql/java-all
version: 7.7.4-dev version: 7.7.5-dev
groups: java groups: java
dbscheme: config/semmlecode.dbscheme dbscheme: config/semmlecode.dbscheme
extractor: java extractor: java

View File

@@ -1,3 +1,10 @@
## 1.10.0
### Query Metadata Changes
* Reduced the `security-severity` score of the `java/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.
* Reduced the `security-severity` score of the `java/insecure-cookie` query from 5.0 to 4.0 to better reflect its impact.
## 1.9.0 ## 1.9.0
### New Queries ### New Queries

View File

@@ -1,5 +1,6 @@
--- ## 1.10.0
category: queryMetadata
--- ### Query Metadata Changes
* Reduced the `security-severity` score of the `java/overly-large-range` query from 5.0 to 4.0 to better reflect its impact. * Reduced the `security-severity` score of the `java/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.
* Reduced the `security-severity` score of the `java/insecure-cookie` query from 5.0 to 4.0 to better reflect its impact. * Reduced the `security-severity` score of the `java/insecure-cookie` query from 5.0 to 4.0 to better reflect its impact.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.9.0 lastReleaseVersion: 1.10.0

View File

@@ -1,5 +1,5 @@
name: codeql/java-queries name: codeql/java-queries
version: 1.9.1-dev version: 1.10.1-dev
groups: groups:
- java - java
- queries - queries

View File

@@ -1,3 +1,7 @@
## 2.6.15
No user-facing changes.
## 2.6.14 ## 2.6.14
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 2.6.15
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 2.6.14 lastReleaseVersion: 2.6.15

View File

@@ -1,5 +1,5 @@
name: codeql/javascript-all name: codeql/javascript-all
version: 2.6.15-dev version: 2.6.16-dev
groups: javascript groups: javascript
dbscheme: semmlecode.javascript.dbscheme dbscheme: semmlecode.javascript.dbscheme
extractor: javascript extractor: javascript

View File

@@ -1,3 +1,10 @@
## 2.2.0
### Query Metadata Changes
* Increased the `security-severity` score of the `js/xss-through-dom` query from 6.1 to 7.8 to align with other XSS queries.
* Reduced the `security-severity` score of the `js/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.
## 2.1.3 ## 2.1.3
No user-facing changes. No user-facing changes.

View File

@@ -1,5 +1,6 @@
--- ## 2.2.0
category: queryMetadata
--- ### Query Metadata Changes
* Increased the `security-severity` score of the `js/xss-through-dom` query from 6.1 to 7.8 to align with other XSS queries. * Increased the `security-severity` score of the `js/xss-through-dom` query from 6.1 to 7.8 to align with other XSS queries.
* Reduced the `security-severity` score of the `js/overly-large-range` query from 5.0 to 4.0 to better reflect its impact. * Reduced the `security-severity` score of the `js/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 2.1.3 lastReleaseVersion: 2.2.0

View File

@@ -1,5 +1,5 @@
name: codeql/javascript-queries name: codeql/javascript-queries
version: 2.1.4-dev version: 2.2.1-dev
groups: groups:
- javascript - javascript
- queries - queries

View File

@@ -1,3 +1,7 @@
## 1.0.35
No user-facing changes.
## 1.0.34 ## 1.0.34
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.0.35
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.0.34 lastReleaseVersion: 1.0.35

View File

@@ -1,4 +1,4 @@
name: codeql/suite-helpers name: codeql/suite-helpers
version: 1.0.35-dev version: 1.0.36-dev
groups: shared groups: shared
warnOnImplicitThis: true warnOnImplicitThis: true

View File

@@ -1,3 +1,9 @@
## 5.0.0
### Breaking Changes
- The classes `ControlFlowNode`, `Expr`, and `Module` no longer expose predicates that invoke the points-to analysis. To access these predicates, import the module `LegacyPointsTo` and follow the instructions given therein.
## 4.1.0 ## 4.1.0
### New Features ### New Features

View File

@@ -1,5 +1,5 @@
--- ## 5.0.0
category: breaking
--- ### Breaking Changes
- The classes `ControlFlowNode`, `Expr`, and `Module` no longer expose predicates that invoke the points-to analysis. To access these predicates, import the module `LegacyPointsTo` and follow the instructions given therein. - The classes `ControlFlowNode`, `Expr`, and `Module` no longer expose predicates that invoke the points-to analysis. To access these predicates, import the module `LegacyPointsTo` and follow the instructions given therein.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 4.1.0 lastReleaseVersion: 5.0.0

View File

@@ -1,5 +1,5 @@
name: codeql/python-all name: codeql/python-all
version: 4.1.1-dev version: 5.0.1-dev
groups: python groups: python
dbscheme: semmlecode.python.dbscheme dbscheme: semmlecode.python.dbscheme
extractor: python extractor: python

View File

@@ -1,3 +1,9 @@
## 1.7.0
### Query Metadata Changes
* Reduced the `security-severity` score of the `py/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.
## 1.6.8 ## 1.6.8
### Minor Analysis Improvements ### Minor Analysis Improvements

View File

@@ -1,4 +0,0 @@
---
category: queryMetadata
---
* Reduced the `security-severity` score of the `py/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.

View File

@@ -0,0 +1,5 @@
## 1.7.0
### Query Metadata Changes
* Reduced the `security-severity` score of the `py/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.6.8 lastReleaseVersion: 1.7.0

View File

@@ -1,5 +1,5 @@
name: codeql/python-queries name: codeql/python-queries
version: 1.6.9-dev version: 1.7.1-dev
groups: groups:
- python - python
- queries - queries

View File

@@ -1,3 +1,7 @@
## 5.1.3
No user-facing changes.
## 5.1.2 ## 5.1.2
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 5.1.3
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 5.1.2 lastReleaseVersion: 5.1.3

View File

@@ -1,5 +1,5 @@
name: codeql/ruby-all name: codeql/ruby-all
version: 5.1.3-dev version: 5.1.4-dev
groups: ruby groups: ruby
extractor: ruby extractor: ruby
dbscheme: ruby.dbscheme dbscheme: ruby.dbscheme

View File

@@ -1,3 +1,9 @@
## 1.5.0
### Query Metadata Changes
* Reduced the `security-severity` score of the `rb/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.
## 1.4.8 ## 1.4.8
No user-facing changes. No user-facing changes.

View File

@@ -1,4 +0,0 @@
---
category: queryMetadata
---
* Reduced the `security-severity` score of the `rb/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.

View File

@@ -0,0 +1,5 @@
## 1.5.0
### Query Metadata Changes
* Reduced the `security-severity` score of the `rb/overly-large-range` query from 5.0 to 4.0 to better reflect its impact.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 1.4.8 lastReleaseVersion: 1.5.0

View File

@@ -1,5 +1,5 @@
name: codeql/ruby-queries name: codeql/ruby-queries
version: 1.4.9-dev version: 1.5.1-dev
groups: groups:
- ruby - ruby
- queries - queries

View File

@@ -1,3 +1,9 @@
## 0.1.20
### Minor Analysis Improvements
* Added models for cookie methods in the `poem` crate.
## 0.1.19 ## 0.1.19
### Major Analysis Improvements ### Major Analysis Improvements

View File

@@ -1,4 +1,5 @@
--- ## 0.1.20
category: minorAnalysis
--- ### Minor Analysis Improvements
* Added models for cookie methods in the `poem` crate. * Added models for cookie methods in the `poem` crate.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 0.1.19 lastReleaseVersion: 0.1.20

View File

@@ -1,5 +1,5 @@
name: codeql/rust-all name: codeql/rust-all
version: 0.1.20-dev version: 0.1.21-dev
groups: rust groups: rust
extractor: rust extractor: rust
dbscheme: rust.dbscheme dbscheme: rust.dbscheme

View File

@@ -1,3 +1,9 @@
## 0.1.20
### Minor Analysis Improvements
* Taint flow barriers have been added to the `rust/regex-injection`, `rust/sql-injection` and `rust/log-injection`, reducing the frequency of false positive results for these queries.
## 0.1.19 ## 0.1.19
### Minor Analysis Improvements ### Minor Analysis Improvements

View File

@@ -1,4 +1,5 @@
--- ## 0.1.20
category: minorAnalysis
--- ### Minor Analysis Improvements
* Taint flow barriers have been added to the `rust/regex-injection`, `rust/sql-injection` and `rust/log-injection`, reducing the frequency of false positive results for these queries. * Taint flow barriers have been added to the `rust/regex-injection`, `rust/sql-injection` and `rust/log-injection`, reducing the frequency of false positive results for these queries.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 0.1.19 lastReleaseVersion: 0.1.20

View File

@@ -1,5 +1,5 @@
name: codeql/rust-queries name: codeql/rust-queries
version: 0.1.20-dev version: 0.1.21-dev
groups: groups:
- rust - rust
- queries - queries

View File

@@ -1,3 +1,7 @@
## 0.0.9
No user-facing changes.
## 0.0.8 ## 0.0.8
No user-facing changes. No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.0.9
No user-facing changes.

View File

@@ -1,2 +1,2 @@
--- ---
lastReleaseVersion: 0.0.8 lastReleaseVersion: 0.0.9

Some files were not shown because too many files have changed in this diff Show More